Vulnerabilities (CVE)

Filtered by vendor Shibboleth Subscribe
Filtered by product Service Provider
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2021-28963 2 Debian, Shibboleth 2 Debian Linux, Service Provider 2021-03-26 5.0 MEDIUM 5.3 MEDIUM
Shibboleth Service Provider before 3.2.1 allows content injection because template generation uses attacker-controlled parameters.